top of page

CAC Generative AI Filings Hit 1,112 as China Speeds Up Compliance

Sep 15
12 min read

CAC generative AI filings increased by 124 services during July and August 2026, pushing China’s national total to 1,112. The batch also included seven services designed to run generative AI on smartphones.

That growth creates a regulatory tension rarely captured by launch announcements. China is allowing more models into public-facing products while expanding the compliance system surrounding them. The result is neither a simple restriction story nor unrestricted deployment.

The filing system now separates developers that directly provide model capabilities from applications built on previously filed models. That distinction puts pressure on both model vendors and downstream product teams. They must decide whether to own the regulatory burden or depend on an approved provider.

CAC Generative AI Filings Added 124 Services in Two Months

The latest figures show that China’s filing system is processing more services without collapsing every AI product into one regulatory category.

The Cyberspace Administration of China published the underlying announcement at 6 p.m. Beijing time on September 14, 2026. The date matters because the original news feed did not provide a verified publication time.

According to the official filing notice, 124 generative AI services completed national filing procedures during July and August. Seven of them provide generative AI directly on mobile devices.

A separate group of 133 applications or features completed registration through local cyberspace authorities. These products access the capabilities of previously filed models through APIs or other technical methods.

By August 31, China had recorded 1,112 filed generative AI services and 731 registered applications or features. Those are cumulative totals, not estimates of monthly active products or unique foundation models.

The distinction between filing and registration is central to the announcement. A company that directly supplies a generative model service faces the national filing route. A downstream application using an already filed model follows a local registration route.

That architecture reflects the increasingly layered structure of the AI market. A foundation-model company can serve many applications, while each application carries its own interface, users, use cases, and content risks.

The numbers also reveal how quickly that downstream layer is expanding. During the two-month period, registered applications outnumbered filed services by nine. This is a limited observation from one reporting window, but it supports a broader shift toward application deployment.

The seven mobile services add another important signal. On-device generative AI processes at least some requests or model operations on a phone instead of relying entirely on remote infrastructure.

Mobile deployment can reduce latency and limit the amount of information transmitted to a cloud server. It also complicates compliance because model behavior becomes distributed across devices, software versions, and hardware configurations.

The CAC did not identify the seven mobile services in the short public notice. The attached filing document provides the formal record, but the announcement offers no performance results or adoption figures.

It also does not describe the time each applicant spent under review. Readers should not interpret 124 filings as 124 approvals submitted and completed within the same two months.

The notice says public-facing providers with public-opinion attributes or social-mobilization capabilities can complete filing or registration through the appropriate local authority. It also requires launched products to disclose the model name and filing or registration identifier prominently.

For users, that disclosure can appear within a product details page or another visible location. For product operators, it turns the underlying model relationship into information that must remain accurate after launch.

A team cannot treat model selection as a private infrastructure decision if the public product identifies that model. Switching providers can affect product behavior, contracts, data handling, and regulatory records at the same time.

The latest batch therefore marks more than an increase in a government database. It shows a compliance system following AI from the model layer into individual products and mobile devices.

China’s AI Filing Pipeline Is Accelerating

China added more filed services in the first eight months of 2026 than it recorded during all of 2025.

The August total of 1,112 represents a rise of 364 filed services since the end of 2025. That calculation follows from the CAC’s published year-end and 2026 batch totals.

China finished 2024 with 302 filed generative AI services. The CAC later reported 446 additions during 2025, taking the total to 748.

The 2025 filing record also counted 330 newly registered applications or features during that year. Combined with 105 registrations at the end of 2024, that produced a 2025 year-end total of 435.

The first 2026 reporting period then added 48 filed services and 46 registered applications. The February totals reached 796 and 481, respectively.

March and April brought another 72 filed services and 49 registrations. The April filing update put the cumulative counts at 868 filed services and 530 registered applications.

May and June added 120 filed services and 68 registrations. That lifted the totals to 988 and 598 before the latest reporting period began.

The July and August additions then produced the current totals of 1,112 filings and 731 registrations. Across the first eight months of 2026, filings grew by about 49 percent from the 2025 year-end level.

Registrations increased by 296 during the same period, a rise of about 68 percent. That faster percentage growth is consistent with more companies packaging existing models into specialized applications.

These comparisons describe the regulatory inventory, not the commercial success of the listed services. A filing does not reveal revenue, user retention, inference volume, or model quality.

It also does not prove that every filed service remains available. Some products can change names, replace underlying models, narrow their availability, or fail to attract meaningful use.

Still, the filing pace carries strategic weight. Developers seeking Chinese consumers now have a growing selection of compliant model providers and an expanding set of application precedents.

That can lower one barrier for downstream development. A product team may register an application built on a filed model instead of operating and filing its own model service.

The arrangement favors vendors that can turn one model into infrastructure for many applications. Cloud providers and model companies can spread compliance work across a larger customer base.

It also gives established platforms an operational advantage. Large companies often have legal, security, evaluation, and content-moderation teams that can maintain records across multiple products.

Smaller developers face a different calculation. Using a third-party model can reduce the initial filing burden, but it creates technical and commercial dependence on the provider.

A change in model access, moderation behavior, pricing policy, or API availability can affect the downstream product. The application developer still remains responsible for what users experience.

The totals therefore represent two forms of expansion. China is increasing the number of model services eligible for public deployment while building a larger application economy above them.

That two-layer growth is the clearest reason the latest notice matters. The compliance system is no longer tracking only prominent foundation models from large technology companies.

It is increasingly tracking the products that place those models inside phones, workplace tools, consumer services, and industry-specific workflows.

Filing Versus Registration Is the Market’s Main Divide

The decisive competition is between companies that own a filed model stack and developers that build products on someone else’s approved infrastructure.

China’s interim rules cover generative AI services offered to the public within the country. They address systems that generate text, images, audio, video, and other content.

The rules took effect on August 15, 2023. They established obligations involving training data, personal information, content governance, user protection, and regulatory cooperation.

Under the interim AI measures, providers must take measures to improve the accuracy and reliability of generated content. They must also protect user input records and avoid collecting unnecessary personal information.

Services with public-opinion attributes or social-mobilization capabilities face security assessment and algorithm filing requirements. Those terms focus the system on public-facing services that can influence information distribution or collective behavior.

The filing route places the model provider closer to the regulatory center. That provider controls training choices, model updates, safety evaluations, and many technical safeguards.

Registration recognizes a different role. An application developer can call a filed model through an API while controlling the user interface, retrieval sources, prompts, tools, and application-specific policies.

This split is practical because a downstream developer usually cannot inspect or change every part of a proprietary model. The developer can still shape the context sent to it and the actions taken with its output.

Consider a workplace assistant that summarizes internal documents. Its model provider controls the base model, while the application operator controls document access, retrieval rules, permissions, and the presentation of answers.

A consumer writing application creates a different risk profile. Its users may publish generated material, so the product needs controls addressing harmful content, attribution, and misuse.

An on-device assistant adds another variation. Some information may remain local, but updates must still preserve expected behavior across supported phones and operating-system versions.

These products can share one underlying model without sharing the same risk. That is why the registration layer matters even when the model has already completed filing.

The structure also shapes competition among Chinese AI providers. A vendor is not competing only on benchmark scores or inference speed. It is competing on whether downstream developers trust its compliance foundation.

Stable documentation, predictable safety behavior, and traceable model versions become product features. They reduce the work required when an application prepares its own registration materials.

Large platforms can bundle these capabilities with cloud hosting and development tools. Independent model companies must show that their infrastructure remains reliable without forcing every customer into a closed product suite.

Application developers face a build-or-buy decision. Owning the model offers more control over training, deployment, and economics, but it also brings the national filing responsibility closer.

Using a filed model speeds development and narrows the infrastructure burden. It can also make product differentiation harder when competitors access similar model capabilities.

That tension becomes sharper as model quality converges. If several filed providers can handle the same common tasks, distribution, proprietary data, workflow design, and user trust carry more weight.

For enterprise buyers, the distinction should guide procurement questions. They need to know which company filed the model, which entity registered the application, and where responsibility changes hands.

They should also verify the exact model version used in production. A broad vendor name does not establish that every model, deployment method, or product configuration shares the same record.

The public notice requires products to identify the model and filing or registration number. That disclosure gives buyers a starting point, though it is not a complete technical audit.

A listed identifier cannot explain retention settings, access controls, retrieval quality, or how human reviewers handle sensitive outputs. Those questions remain part of normal vendor assessment.

The market divide is therefore not regulation versus innovation. It is direct control versus delegated infrastructure, with different costs and dependencies attached to each route.

What the Filing Numbers Do Not Prove

A completed filing indicates passage through a regulatory process, but it does not certify that a service is accurate, secure, competitive, or widely used.

The CAC announcement contains counts and procedural instructions. It does not publish aggregate model evaluations, incident rates, processing times, or rejection figures.

Without the number of unsuccessful or withdrawn applications, observers cannot calculate an approval rate. They also cannot determine whether the larger batches reflect faster reviews, more submissions, or both.

The word “filing” can create another misunderstanding. It should not be treated as a general government endorsement of every response a model generates.

Generative systems remain probabilistic, meaning they produce outputs based on learned patterns rather than retrieving a guaranteed correct answer. A compliant model can still hallucinate facts or misunderstand a request.

The filing total also counts services, not necessarily distinct technical foundations. One organization can operate several services based on related model families or configurations.

Likewise, one filed model can support many registered applications. Adding the two totals would not produce a meaningful count of independent models or companies.

This measurement problem limits international comparisons. The European Union organizes much of its AI governance around risk categories and provider obligations, while other markets emphasize voluntary testing or sector rules.

China’s published filing inventory is unusually concrete, but it measures participation in China’s own system. It cannot be directly compared with model releases, startup counts, or regulatory registrations elsewhere.

The application figures require similar caution. A registered feature may sit inside a larger product, and its registration says nothing about how often users activate it.

A productivity application with millions of users and a narrow AI function can appear as one entry. A specialized application with little adoption can also appear as one entry.

The seven on-device services raise additional unanswered questions. The announcement does not explain how much processing occurs locally or which tasks still require cloud access.

“On-device” can describe several architectures. A compact model may run entirely on a phone, or the device may handle limited tasks before sending complex requests to a server.

Hybrid systems can improve performance while preserving access to larger models. They also create more complicated data maps because information can move between local storage, cloud systems, and third-party services.

Regulators and buyers need version visibility in that environment. A mobile model can change through application updates, operating-system releases, or downloadable model packages.

The filing notice does not explain how material updates are treated. The interim measures refer to filing, modification, and cancellation procedures under related algorithm rules, but implementation details matter.

Companies must decide when a product change affects the existing record. A new interface may be minor, while a new model, modality, or autonomous action can alter the risk profile.

The broader compliance burden also extends beyond the generative AI filing itself. China’s deep-synthesis rules include requirements involving user authentication, content management, training-data security, and synthetic-content labels.

Those overlapping obligations make the public filing count only one part of the picture. Data protection, cybersecurity, content controls, and sector-specific rules can still apply.

A healthcare assistant, financial tool, or educational service faces questions that a general chatbot may not encounter. The underlying model record does not replace those product-level responsibilities.

Foreign developers should be especially cautious about broad conclusions. The interim rules focus on services offered to the Chinese public, but market entry can involve additional data, licensing, infrastructure, and partnership considerations.

Using a filed Chinese model does not automatically settle every obligation. The product’s intended users, operating entity, deployment location, and information flows still matter.

The same caution applies to enterprise buyers outside China. A filing can provide evidence that a provider has completed a defined process, but it should not replace security and privacy review.

Buyers still need contractual terms covering data use, retention, subprocessors, incidents, model updates, and service continuity. They also need their own tests for accuracy and harmful behavior.

The filing system creates visibility, but not complete transparency. It tells the market that a service has entered the regulatory framework without revealing every evaluation behind that result.

That distinction is the central skeptical point. More filings demonstrate regulatory throughput and developer activity, not automatic proof of trustworthy or commercially successful AI.

Three Signals Will Show What Happens Next

The next phase will be decided by application growth, mobile implementation, and the treatment of major model updates.

The first signal is the balance between new filings and downstream registrations in the next CAC release. The July and August batch added 124 services and 133 applications or features.

If registrations continue growing faster, the market is moving toward product specialization above shared model infrastructure. That would strengthen the view that compliance is becoming a platform advantage.

A reversal would matter just as much. If filings rise while registrations slow, developers may be bringing more proprietary models to market or struggling to convert available models into products.

The cumulative totals alone will not settle that question. The mix inside each new batch will show which layer attracts more activity.

The second signal is how regulators document on-device generative AI. The seven mobile services represent a small share of the latest batch, but they introduce a distinct deployment model.

Future notices could identify more local or hybrid services. Product pages may also provide clearer disclosures about which model runs on the device and which requests reach external servers.

That information will influence privacy claims. Local processing can reduce transmission, but only if the relevant task and data actually remain on the device.

It will also affect hardware competition. Smaller models must fit within limits involving memory, battery use, temperature, and processor capacity while still delivering useful answers.

If more mobile services complete filing, developers will gain precedents for deploying compact models at scale. That would strengthen the case that China’s compliance framework can accommodate decentralized inference.

If mobile entries remain rare, technical limits or regulatory complexity may be slowing adoption. Either result will help distinguish a meaningful shift from a single batch detail.

The third signal is how the system handles major model and product changes. A static filing record becomes less informative when providers update models frequently.

Developers need clarity about which changes require a modification procedure. Regulators need records that remain accurate without turning every routine update into a new filing.

This question becomes urgent as models add modalities and tools. A text assistant can later gain image generation, voice interaction, web access, or the ability to complete actions.

Each capability changes what the product can do and how it can fail. A model that only drafts text presents a different risk from an agent that sends messages or changes business records.

Watch for more visible version identifiers in product disclosures and filing materials. Clear version mapping would help users, enterprise buyers, and downstream developers connect a live service to its regulatory record.

The absence of that mapping would weaken the filing system’s practical value. A number displayed inside an application helps little if nobody can tell which production model it covers.

These three signals matter more than the next headline count by itself. Registrations reveal whether application development is broadening, mobile records test new deployment patterns, and version handling determines whether oversight stays current.

For developers, the immediate lesson is operational. Model selection now affects compliance architecture, vendor dependence, and future product changes, not only output quality.

For enterprise buyers, the latest CAC generative AI filings provide a useful verification point. They should prompt deeper questions about the entity behind a model and the application layered above it.

For knowledge workers, visible filing identifiers can help distinguish accountable public services from tools with unclear origins. Those identifiers still need to be paired with careful handling of sensitive information.

China’s 1,112 filed services show that formal oversight has not stopped public AI deployment. They also show that every new layer of adoption creates another layer of responsibility.

The next CAC release should be read as a map of that responsibility, not a scoreboard. Check whether applications keep outpacing models, whether mobile AI expands, and whether disclosures identify the versions users actually receive.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page